What we collect, and how we handle it.
The short version: we collect what the service needs to run your tasks, we use only essential cookies, we don't sell personal data or run ad trackers, and you can ask us to delete yours. The long version follows. Last updated August 20, 2026.
1. What we collect
- Account details. Your name and email address, provided through Firebase Authentication — including Google sign-in if you use it — plus which workspaces you belong to and your role in each.
- What you give Browza to work with. The tasks you submit, the agents you configure (their goals, instructions, and schedules), the skills you teach, and any parameters you pass to a run.
- What your runs produce. Results, step-by-step run events, logs, and screenshots. Screenshot capture is configurable per run (every step, final only, or off), and artifacts are stored so your workspace can read its own history back.
- Browser profile state. A persistent profile deliberately keeps the cookies and signed-in sessions you placed in it, so runs can resume without re-authenticating. That is the feature, stored to provide it — and it is yours: we operate those sessions only on your instructions.
- Page content, transiently. To complete a task, Browza reads the pages the task visits, and relevant page content is processed by the AI model driving the run. What persists afterward is what belongs to your run: the results, events, and artifacts above — not a copy of the web pages themselves.
- Payment details. Handled by our payment processor when you buy a plan; we don't store full card numbers on our systems.
- Usage and diagnostics. Operational logs, error reports, and usage metrics (how many runs, how many steps) that keep the service healthy and billable. We do not run third-party advertising or analytics trackers on the site.
2. What the recorder never takes
When you teach Browza by recording a task in your own browser, the extension captures the structure of what you did — the steps, never the secrets. Concretely:
- Password fields, card fields, and one-time codes are never recorded — a recording that touches an identity form is discarded entirely, not partially kept.
- Values you type stay in your browser's session storage and are deliberately not persisted across a browser restart; only a value you explicitly promote to a reusable constant is ever transmitted, and it is stored separately.
- Page text, titles, and screenshots of the pages you visit are not transmitted by the recorder. Step thumbnails, where enabled, stay on your device and are purged with its local vault. A stitched review filmstrip is created only with an explicit per-recording opt-in, and it is stripped before the recording is stored server-side.
3. How we use it
To provide the service: run your tasks, store and show your results, keep you signed in, remember your workspace, support you when something breaks, secure the platform, enforce our terms, and bill for usage. We do not sell personal data, we do not use your data for advertising, and we do not use your content to train AI models.
4. Why we're allowed to
Where the law asks for a legal basis, ours are the ordinary ones:
- Performing our contract with you — running your tasks, storing your results, operating your account.
- Legitimate interests — securing the platform, preventing abuse, and understanding aggregate usage, in ways that don't override your rights.
- Legal obligations — records we must keep, and lawful requests we must answer.
- Consent — for anything optional, asked at the moment it applies (like the recorder's filmstrip opt-in), and withdrawable.
6. Who processes it
- Google Cloud — our infrastructure: application hosting, databases, and artifact storage.
- Firebase Authentication (Google) — sign-in, including Google sign-in.
- AI model providers — the model configured for your workspace processes task text and relevant page content in order to plan and act. Model API keys you configure are stored as references to a secret store, never as raw values in our database.
- A payment processor — for paid plans.
Each processes data only to provide their part of the service, under their own contractual obligations to us. We don't share personal data with anyone else except as required by law, and if we are ever legally compelled to disclose your data, we will tell you unless the law forbids it.
7. Learned data: procedures, skills, and the site graph
Browza gets better with use. Because “the service learns” can mean very different things, here is exactly what is kept, at which scope, and what is excluded by rule:
Procedures your workspace learns. When a run succeeds, Browza may remember how it was done — the sequence of actions that worked — so a repeat of the same task is faster and cheaper. These procedures belong to your workspace only and are matched conservatively (same workspace, same site, closely matching intent). Some things are never memorized into a procedure, by rule: credentials, one-time codes, single-use links, and raw screen coordinates. A step involving any of those disqualifies the whole procedure from being remembered — it is not partially kept.
Skills you teach. A skill recorded with the Browza extension is compiled from the structural steps of your demonstration (section 2 lists what the recorder never captures). Skills live in your workspace, are runnable by name, and are not used automatically for similar-looking tasks until a person in your workspace explicitly turns automatic use on. They are never shared across customers, and they never feed the shared graph described next.
The shared site graph. Browza maintains a map of the public web's structure — which pages a site has, what state each page represents, which controls exist, and which action leads where. This graph is what makes runs fast and reliable for everyone, and its privacy properties are design rules, not afterthoughts:
- It is content-free by construction: no page text, no personal data, no credentials, no typed values, no results — the graph records that a “search box” exists, never what anyone typed into it.
- Structure reaches the shared tier only when independent observations agree on it verbatim — a name or shape seen by a single workspace stays with that workspace.
- Nothing taught enters it. Recorded demonstrations and skills write to your workspace's own storage only, never to the shared graph.
- Where a site issues account-specific, id-addressed pages, learned structure is bounded and consent-scoped per address rather than generalized.
In short: what is specific to you stays yours; what is shared is the anatomy of public websites — the same thing any visitor sees — not anyone's content. Questions about any of this are welcome at hello@employy.co.
8. Isolation
Everything is scoped to your workspace: runs, profiles, results, skills, agents, and API keys carry your workspace's identity, and there is no cross-workspace read. Browser sessions run isolated, with no shared browser state between customers.
9. Security
- Traffic is encrypted in transit (TLS); data is encrypted at rest on Google Cloud.
- Session cookies are httpOnly and secure; the one non-httpOnly cookie is a yes/no flag that carries no secret.
- API keys are stored as hashes — we cannot read your key back, only verify it.
- Model API keys are stored as secret references, and Browza never memorizes credentials or one-time codes into anything replayable.
- Access to production systems is restricted and logged. No security is perfect; if an incident affects your data, we will inform you without undue delay.
10. Where data lives
Our infrastructure runs on Google Cloud in the United States (primarily the us-east4 region). If you use Browza from elsewhere, your data is transferred to and processed in the United States. Runs can route their browsing traffic through the egress region you choose; that choice affects where the browser appears to be, not where your stored data lives.
11. Retention and deletion
We keep your data while your account is active so your histories, profiles, agents, and skills keep working. You can delete individual items from the dashboard where the surface provides it. To delete your account and its data, write to hello@employy.co — we act on deletion requests within 30 days, keeping only what the law requires us to keep (such as billing records) for as long as it requires.
12. Automated decisions
Browza automates browser work you explicitly ask for — that is the product. What we do not do is make automated decisions about you with legal or similarly significant effect: no automated credit decisions, no profiling that gates your access, no scoring of users. Where an agent is set to ask before acting, a person's approval is exactly what it waits for.
13. Your rights and choices
Depending on where you live — the GDPR in the EEA and UK, the CCPA/CPRA in California, and similar laws elsewhere — you may have rights to access, correct, export, delete, or object to processing of your personal data. We honor the substance of those rights for everyone, wherever you are: email hello@employy.co and we will respond within 30 days. You can also choose not to use the features that store more — profiles, screenshots, the recorder — and each degrades gracefully rather than gating the rest of the product. If you use Google sign-in, Google's own privacy policy governs what Google does on their side. If you believe we have handled your data wrongly, we would like to hear it first, but you also have the right to complain to your local data-protection authority.
14. Children
Browza is not directed at children and may not be used by anyone under 16. If you believe a child has created an account, tell us and we will delete it.
15. When this policy changes
This page changes with our practices, never after them: if a data practice changes, the change lands here first. The date at the top always reflects the current revision, and how you find out depends on the change:
- Material changes — collecting a new category of data, a new purpose, a new subprocessor category, or anything that reduces your rights — are announced at least 14 days before they take effect, by email to your account address and by a visible notice on the site. Where a change needs your consent, we ask for it rather than assume it.
- Non-material changes — clarifications, renamed features, fixed typos — take effect when published, with the date updated.
- Previous versions are available on request, so you can see exactly what changed and when.
Questions or requests: hello@employy.co. The terms of service live here.
